{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,25]],"date-time":"2026-07-25T15:59:19Z","timestamp":1784995159779,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":89,"publisher":"ACM","license":[{"start":{"date-parts":[[2021,4,19]],"date-time":"2021-04-19T00:00:00Z","timestamp":1618790400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2021,4,19]]},"DOI":"10.1145\/3442381.3449965","type":"proceedings-article","created":{"date-parts":[[2021,6,3]],"date-time":"2021-06-03T19:37:45Z","timestamp":1622749065000},"page":"669-680","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":36,"title":["Not All Features Are Equal: Discovering Essential Features for Preserving Prediction Privacy"],"prefix":"10.1145","author":[{"given":"Fatemehsadat","family":"Mireshghallah","sequence":"first","affiliation":[{"name":"University of California, San Diego, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mohammadkazem","family":"Taram","sequence":"additional","affiliation":[{"name":"University of California, San Diego, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ali","family":"Jalali","sequence":"additional","affiliation":[{"name":"Amazon, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ahmed Taha Taha","family":"Elthakeb","sequence":"additional","affiliation":[{"name":"University of California, San Diego, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Dean","family":"Tullsen","sequence":"additional","affiliation":[{"name":"University of California, San Diego, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Hadi","family":"Esmaeilzadeh","sequence":"additional","affiliation":[{"name":"University of California, San Diego, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2021,6,3]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"Deep Learning with Differential Privacy. In ACM Conference on Computer and Communications Security (CCS).","author":"Abadi Martin","year":"2016","unstructured":"Martin Abadi , Andy Chu , Ian Goodfellow , H.\u00a0 Brendan McMahan , Ilya Mironov , Kunal Talwar , and Li Zhang . 2016 . Deep Learning with Differential Privacy. In ACM Conference on Computer and Communications Security (CCS). Martin Abadi, Andy Chu, Ian Goodfellow, H.\u00a0Brendan McMahan, Ilya Mironov, Kunal Talwar, and Li Zhang. 2016. Deep Learning with Differential Privacy. In ACM Conference on Computer and Communications Security (CCS)."},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3339819"},{"key":"e_1_3_2_1_3_1","volume-title":"International Conference on Machine Learning (ICML).","author":"Arpit Devansh","year":"2017","unstructured":"Devansh Arpit , Stanislaw Jastrzkebski , Nicolas Ballas , David Krueger , Emmanuel Bengio , Maxinder\u00a0 S Kanwal , Tegan Maharaj , Asja Fischer , Aaron Courville , Yoshua Bengio , 2017 . A closer look at memorization in deep networks . In International Conference on Machine Learning (ICML). Devansh Arpit, Stanislaw Jastrzkebski, Nicolas Ballas, David Krueger, Emmanuel Bengio, Maxinder\u00a0S Kanwal, Tegan Maharaj, Asja Fischer, Aaron Courville, Yoshua Bengio, 2017. A closer look at memorization in deep networks. In International Conference on Machine Learning (ICML)."},{"key":"e_1_3_2_1_4_1","volume-title":"28th {USENIX} Security Symposium ({USENIX} Security 19). 1697\u20131714.","author":"Azad Babak\u00a0Amin","unstructured":"Babak\u00a0Amin Azad , Pierre Laperdrix , and Nick Nikiforakis . 2019. Less is more: quantifying the security benefits of debloating web applications . In 28th {USENIX} Security Symposium ({USENIX} Security 19). 1697\u20131714. Babak\u00a0Amin Azad, Pierre Laperdrix, and Nick Nikiforakis. 2019. Less is more: quantifying the security benefits of debloating web applications. In 28th {USENIX} Security Symposium ({USENIX} Security 19). 1697\u20131714."},{"key":"e_1_3_2_1_5_1","unstructured":"Borja Balle Peter Kairouz H\u00a0Brendan McMahan Om Thakkar and Abhradeep Thakurta. 2020. Privacy amplification via random check-ins. arXiv preprint arXiv:2007.06605(2020).  Borja Balle Peter Kairouz H\u00a0Brendan McMahan Om Thakkar and Abhradeep Thakurta. 2020. Privacy amplification via random check-ins. arXiv preprint arXiv:2007.06605(2020)."},{"key":"e_1_3_2_1_6_1","volume-title":"Now You Don\u2019t: A Large-scale Analysis of Early Domain Deletions. In 22nd International Symposium on Research in Attacks, Intrusions and Defenses (RAID 2019","author":"Barron Timothy","year":"2019","unstructured":"Timothy Barron , Najmeh Miramirkhani , and Nick Nikiforakis . 2019 . Now You See It , Now You Don\u2019t: A Large-scale Analysis of Early Domain Deletions. In 22nd International Symposium on Research in Attacks, Intrusions and Defenses (RAID 2019 ). USENIX Association, Chaoyang District, Beijing, 383\u2013397. https:\/\/www.usenix.org\/conference\/raid 2019\/presentation\/barron Timothy Barron, Najmeh Miramirkhani, and Nick Nikiforakis. 2019. Now You See It, Now You Don\u2019t: A Large-scale Analysis of Early Domain Deletions. In 22nd International Symposium on Research in Attacks, Intrusions and Defenses (RAID 2019). USENIX Association, Chaoyang District, Beijing, 383\u2013397. https:\/\/www.usenix.org\/conference\/raid2019\/presentation\/barron"},{"key":"e_1_3_2_1_7_1","volume-title":"Beaudry and Renato Renner","author":"J.","year":"2011","unstructured":"Normand\u00a0 J. Beaudry and Renato Renner . 2011 . An intuitive proof of the data processing inequality. arXiv preprint arXiv:1107.0740(2011). arxiv:1107.0740\u00a0[quant-ph] Normand\u00a0J. Beaudry and Renato Renner. 2011. An intuitive proof of the data processing inequality. arXiv preprint arXiv:1107.0740(2011). arxiv:1107.0740\u00a0[quant-ph]"},{"key":"e_1_3_2_1_8_1","unstructured":"Charles Blundell Julien Cornebise Koray Kavukcuoglu and Daan Wierstra. 2015. Weight uncertainty in neural networks. arXiv preprint arXiv:1505.05424(2015).  Charles Blundell Julien Cornebise Koray Kavukcuoglu and Daan Wierstra. 2015. Weight uncertainty in neural networks. arXiv preprint arXiv:1505.05424(2015)."},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/3407023.3407045"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3133982"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-56877-1_7"},{"key":"e_1_3_2_1_12_1","volume-title":"Advances in Neural Information Processing Systems 21, D.\u00a0Koller, D.\u00a0Schuurmans, Y.\u00a0Bengio, and L.\u00a0Bottou (Eds.). Curran Associates","author":"Chaudhuri Kamalika","unstructured":"Kamalika Chaudhuri and Claire Monteleoni . 2009. Privacy-preserving logistic regression . In Advances in Neural Information Processing Systems 21, D.\u00a0Koller, D.\u00a0Schuurmans, Y.\u00a0Bengio, and L.\u00a0Bottou (Eds.). Curran Associates , Inc ., 289\u2013296. http:\/\/papers.nips.cc\/paper\/3486-privacy-preserving-logistic-regression.pdf Kamalika Chaudhuri and Claire Monteleoni. 2009. Privacy-preserving logistic regression. In Advances in Neural Information Processing Systems 21, D.\u00a0Koller, D.\u00a0Schuurmans, Y.\u00a0Bengio, and L.\u00a0Bottou (Eds.). Curran Associates, Inc., 289\u2013296. http:\/\/papers.nips.cc\/paper\/3486-privacy-preserving-logistic-regression.pdf"},{"key":"e_1_3_2_1_13_1","unstructured":"Kamalika Chaudhuri Claire Monteleoni and Anand\u00a0D. Sarwate. 2009. Differentially Private Empirical Risk Minimization. arXiv preprint arXiv:0912.0071(2009). arxiv:0912.0071\u00a0[cs.LG]  Kamalika Chaudhuri Claire Monteleoni and Anand\u00a0D. Sarwate. 2009. Differentially Private Empirical Risk Minimization. arXiv preprint arXiv:0912.0071(2009). arxiv:0912.0071\u00a0[cs.LG]"},{"key":"e_1_3_2_1_14_1","first-page":"1","article-title":"A Near-Optimal Algorithm for Differentially-Private Principal Components","volume":"14","author":"Chaudhuri Kamalika","year":"2013","unstructured":"Kamalika Chaudhuri , Anand\u00a0 D. Sarwate , and Kaushik Sinha . 2013 . A Near-Optimal Algorithm for Differentially-Private Principal Components . J. Mach. Learn. Res. 14 , 1 (Jan. 2013), 2905\u20132943. Kamalika Chaudhuri, Anand\u00a0D. Sarwate, and Kaushik Sinha. 2013. A Near-Optimal Algorithm for Differentially-Private Principal Components. J. Mach. Learn. Res. 14, 1 (Jan. 2013), 2905\u20132943.","journal-title":"J. Mach. Learn. Res."},{"key":"e_1_3_2_1_15_1","volume-title":"Elements of information theory","author":"Cover M","unstructured":"Thomas\u00a0 M Cover and Joy\u00a0 A Thomas . 2012. Elements of information theory . John Wiley & Sons . Thomas\u00a0M Cover and Joy\u00a0A Thomas. 2012. Elements of information theory. John Wiley & Sons."},{"key":"e_1_3_2_1_16_1","volume-title":"ACM Conference on Computer and Communications Security (CCS).","author":"W.","unstructured":"Paul\u00a0 W. Cuff and Lanqing Yu. 2016. Differential Privacy as a Mutual Information Constraint . In ACM Conference on Computer and Communications Security (CCS). Paul\u00a0W. Cuff and Lanqing Yu. 2016. Differential Privacy as a Mutual Information Constraint. In ACM Conference on Computer and Communications Security (CCS)."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/2567948.2577355"},{"key":"e_1_3_2_1_18_1","volume-title":"International Conference on Machine Learning (ICML).","author":"Dowlin Nathan","year":"2016","unstructured":"Nathan Dowlin , Ran Gilad-Bachrach , Kim Laine , Kristin Lauter , Michael Naehrig , and John Wernsing . 2016 . CryptoNets: Applying Neural Networks to Encrypted Data with High Throughput and Accuracy . In International Conference on Machine Learning (ICML). Nathan Dowlin, Ran Gilad-Bachrach, Kim Laine, Kristin Lauter, Michael Naehrig, and John Wernsing. 2016. CryptoNets: Applying Neural Networks to Encrypted Data with High Throughput and Accuracy. In International Conference on Machine Learning (ICML)."},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1007\/11761679_29"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1007\/11681878_14"},{"key":"e_1_3_2_1_21_1","volume-title":"The Algorithmic Foundations of Differential Privacy. Found. Trends Theor. Comput. Sci. 9 (Aug","author":"Dwork Cynthia","year":"2014","unstructured":"Cynthia Dwork and Aaron Roth . 2014. The Algorithmic Foundations of Differential Privacy. Found. Trends Theor. Comput. Sci. 9 (Aug . 2014 ), 211\u2013407. https:\/\/doi.org\/10.1561\/0400000042 10.1561\/0400000042 Cynthia Dwork and Aaron Roth. 2014. The Algorithmic Foundations of Differential Privacy. Found. Trends Theor. Comput. Sci. 9 (Aug. 2014), 211\u2013407. https:\/\/doi.org\/10.1561\/0400000042"},{"key":"e_1_3_2_1_22_1","volume-title":"A research tool for secure machine learning in PyTorch. online\u2013accessed","year":"2020","unstructured":"Facebook. 2019. A research tool for secure machine learning in PyTorch. online\u2013accessed June 2020 , url: https:\/\/crypten.ai. Facebook. 2019. A research tool for secure machine learning in PyTorch. online\u2013accessed June 2020, url: https:\/\/crypten.ai."},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"crossref","unstructured":"Bo Feng Qian Lou Lei Jiang and Geoffrey\u00a0C Fox. 2020. CryptoGRU: Low Latency Privacy-Preserving Text Analysis With GRU. arXiv preprint arXiv:2010.11796(2020).  Bo Feng Qian Lou Lei Jiang and Geoffrey\u00a0C Fox. 2020. CryptoGRU: Low Latency Privacy-Preserving Text Analysis With GRU. arXiv preprint arXiv:2010.11796(2020).","DOI":"10.18653\/v1\/2021.emnlp-main.156"},{"key":"e_1_3_2_1_24_1","unstructured":"Lucjan Hanzlik Yang Zhang Kathrin Grosse Ahmed Salem Max Augustin Michael Backes and Mario Fritz. 2018. MLCapsule: Guarded Offline Deployment of Machine Learning as a Service. arXiv preprint arXiv:1808.00590(2018). arxiv:1808.00590\u00a0[cs.CR]  Lucjan Hanzlik Yang Zhang Kathrin Grosse Ahmed Salem Max Augustin Michael Backes and Mario Fritz. 2018. MLCapsule: Guarded Offline Deployment of Machine Learning as a Service. arXiv preprint arXiv:1808.00590(2018). arxiv:1808.00590\u00a0[cs.CR]"},{"key":"e_1_3_2_1_25_1","unstructured":"Hanieh Hashemi Yongqin Wang and Murali Annavaram. 2020. DarKnight: A Data Privacy Scheme for Training and Inference of Deep Neural Networks. arXiv preprint arXiv:2006.01300(2020).  Hanieh Hashemi Yongqin Wang and Murali Annavaram. 2020. DarKnight: A Data Privacy Scheme for Training and Inference of Deep Neural Networks. arXiv preprint arXiv:2006.01300(2020)."},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/3359789.3359824"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363201"},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.5555\/2612156.2612158"},{"key":"e_1_3_2_1_30_1","volume-title":"GAZELLE: A Low Latency Framework for Secure Neural Network Inference. In USENIX Security Symposium (USENIX Security).","author":"Juvekar Chiraag","year":"2018","unstructured":"Chiraag Juvekar , Vinod Vaikuntanathan , and Anantha Chandrakasan . 2018 . GAZELLE: A Low Latency Framework for Secure Neural Network Inference. In USENIX Security Symposium (USENIX Security). Chiraag Juvekar, Vinod Vaikuntanathan, and Anantha Chandrakasan. 2018. GAZELLE: A Low Latency Framework for Secure Neural Network Inference. In USENIX Security Symposium (USENIX Security)."},{"key":"e_1_3_2_1_31_1","unstructured":"Peter Kairouz Jiachun Liao Chong Huang and Lalitha Sankar. 2019. Censored and Fair Universal Representations using Generative Adversarial Models. arXiv preprint arXiv:1910.00411(2019). arxiv:1910.00411\u00a0[cs.LG]  Peter Kairouz Jiachun Liao Chong Huang and Lalitha Sankar. 2019. Censored and Fair Universal Representations using Generative Adversarial Models. arXiv preprint arXiv:1910.00411(2019). arxiv:1910.00411\u00a0[cs.LG]"},{"key":"e_1_3_2_1_32_1","unstructured":"Peter Kairouz H\u00a0Brendan McMahan Brendan Avent Aur\u00e9lien Bellet Mehdi Bennis Arjun\u00a0Nitin Bhagoji Keith Bonawitz Zachary Charles Graham Cormode Rachel Cummings 2019. Advances and open problems in federated learning. arXiv preprint arXiv:1912.04977(2019).  Peter Kairouz H\u00a0Brendan McMahan Brendan Avent Aur\u00e9lien Bellet Mehdi Bennis Arjun\u00a0Nitin Bhagoji Keith Bonawitz Zachary Charles Graham Cormode Rachel Cummings 2019. Advances and open problems in federated learning. arXiv preprint arXiv:1912.04977(2019)."},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISIT.2017.8007053"},{"key":"e_1_3_2_1_34_1","volume-title":"Basics","author":"Kalos H.","unstructured":"Malvin\u00a0 H. Kalos and Paula\u00a0 A. Whitlock . 1986. Monte Carlo Methods . Vol. 1 : Basics . Wiley-Interscience , USA. Malvin\u00a0H. Kalos and Paula\u00a0A. Whitlock. 1986. Monte Carlo Methods. Vol. 1: Basics. Wiley-Interscience, USA."},{"key":"e_1_3_2_1_35_1","volume-title":"Spectre Attacks: Exploiting Speculative Execution. In IEEE Symposium on Security and Privacy (S&P).","author":"Kocher Paul","year":"2019","unstructured":"Paul Kocher , Jann Horn , Anders Fogh , , Daniel Genkin , Daniel Gruss , Werner Haas , Mike Hamburg , Moritz Lipp , Stefan Mangard , Thomas Prescher , Michael Schwarz , and Yuval Yarom . 2019 . Spectre Attacks: Exploiting Speculative Execution. In IEEE Symposium on Security and Privacy (S&P). Paul Kocher, Jann Horn, Anders Fogh, , Daniel Genkin, Daniel Gruss, Werner Haas, Mike Hamburg, Moritz Lipp, Stefan Mangard, Thomas Prescher, Michael Schwarz, and Yuval Yarom. 2019. Spectre Attacks: Exploiting Speculative Execution. In IEEE Symposium on Security and Privacy (S&P)."},{"key":"e_1_3_2_1_36_1","unstructured":"Kalpesh Krishna Gaurav\u00a0Singh Tomar Ankur\u00a0P Parikh Nicolas Papernot and Mohit Iyyer. 2019. Thieves on sesame street! model extraction of bert-based apis. arXiv preprint arXiv:1910.12366(2019).  Kalpesh Krishna Gaurav\u00a0Singh Tomar Ankur\u00a0P Parikh Nicolas Papernot and Mohit Iyyer. 2019. Thieves on sesame street! model extraction of bert-based apis. arXiv preprint arXiv:1910.12366(2019)."},{"key":"e_1_3_2_1_37_1","unstructured":"Alex Krizhevsky Vinod Nair and Geoffrey Hinton. [n.d.]. CIFAR-100 (Canadian Institute for Advanced Research). ([n.\u00a0d.]). http:\/\/www.cs.toronto.edu\/~kriz\/cifar.html url: http:\/\/www.cs.toronto.edu\/~kriz\/cifar.html.  Alex Krizhevsky Vinod Nair and Geoffrey Hinton. [n.d.]. CIFAR-100 (Canadian Institute for Advanced Research). ([n.\u00a0d.]). http:\/\/www.cs.toronto.edu\/~kriz\/cifar.html url: http:\/\/www.cs.toronto.edu\/~kriz\/cifar.html."},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1145\/3065386"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"crossref","unstructured":"Yann LeCun. 1998. Gradient-based learning applied to document recognition.  Yann LeCun. 1998. Gradient-based learning applied to document recognition.","DOI":"10.1109\/5.726791"},{"key":"e_1_3_2_1_40_1","volume-title":"The MNIST Dataset Of Handwritten Digits. online accessed","author":"LeCun Yann","year":"2019","unstructured":"Yann LeCun and Corinna Cortes . [n.d.]. The MNIST Dataset Of Handwritten Digits. online accessed May 2019 https:\/\/doi.org\/10.1145\/1367497.1367564. 10.1145\/1367497.1367564 Yann LeCun and Corinna Cortes. [n.d.]. The MNIST Dataset Of Handwritten Digits. online accessed May 2019 https:\/\/doi.org\/10.1145\/1367497.1367564."},{"key":"e_1_3_2_1_41_1","unstructured":"Sam Leroux Tim Verbelen Pieter Simoens and Bart Dhoedt. 2018. Privacy Aware Offloading of Deep Neural Networks. arxiv:1805.12024\u00a0[cs.LG]  Sam Leroux Tim Verbelen Pieter Simoens and Bart Dhoedt. 2018. Privacy Aware Offloading of Deep Neural Networks. arxiv:1805.12024\u00a0[cs.LG]"},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"crossref","unstructured":"Jiachun Liao Oliver Kosut Lalitha Sankar and Fl\u00e1vio\u00a0P. Calmon. 2017. A General Framework for Information Leakage.  Jiachun Liao Oliver Kosut Lalitha Sankar and Fl\u00e1vio\u00a0P. Calmon. 2017. A General Framework for Information Leakage.","DOI":"10.1109\/ISIT.2018.8437307"},{"key":"e_1_3_2_1_43_1","volume-title":"USENIX Security Symposium (USENIX Security).","author":"Lipp Moritz","year":"2018","unstructured":"Moritz Lipp , Michael Schwarz , Daniel Gruss , Thomas Prescher , Werner Haas , Anders Fogh , Jann Horn , Stefan Mangard , Paul Kocher , Daniel Genkin , Yuval Yarom , and Mike Hamburg . 2018 . Meltdown: Reading Kernel Memory from User Space . In USENIX Security Symposium (USENIX Security). Moritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher, Werner Haas, Anders Fogh, Jann Horn, Stefan Mangard, Paul Kocher, Daniel Genkin, Yuval Yarom, and Mike Hamburg. 2018. Meltdown: Reading Kernel Memory from User Space. In USENIX Security Symposium (USENIX Security)."},{"key":"e_1_3_2_1_44_1","unstructured":"C. Liu S. Chakraborty and P. Mittal. 2017. DEEProtect: Enabling Inference-based Access Control on Mobile Sensing Applications. ArXiv abs\/1702.06159(2017).  C. Liu S. Chakraborty and P. Mittal. 2017. DEEProtect: Enabling Inference-based Access Control on Mobile Sensing Applications. ArXiv abs\/1702.06159(2017)."},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134056"},{"key":"e_1_3_2_1_46_1","unstructured":"Zaoxing Liu Tian Li Virginia Smith and Vyas Sekar. 2019. Enhancing the privacy of federated learning with sketching. arXiv preprint arXiv:1911.01812(2019).  Zaoxing Liu Tian Li Virginia Smith and Vyas Sekar. 2019. Enhancing the privacy of federated learning with sketching. arXiv preprint arXiv:1911.01812(2019)."},{"key":"e_1_3_2_1_47_1","volume-title":"Deep Learning Face Attributes in the Wild. In International Conference on Computer Vision (ICCV).","author":"Liu Ziwei","year":"2015","unstructured":"Ziwei Liu , Ping Luo , Xiaogang Wang , and Xiaoou Tang . 2015 . Deep Learning Face Attributes in the Wild. In International Conference on Computer Vision (ICCV). Ziwei Liu, Ping Luo, Xiaogang Wang, and Xiaoou Tang. 2015. Deep Learning Face Attributes in the Wild. In International Conference on Computer Vision (ICCV)."},{"key":"e_1_3_2_1_48_1","unstructured":"Qian Lou Bian Song and Lei Jiang. 2020. AutoPrivacy: Automated Layer-wise Parameter Selection for Secure Neural Network Inference. arXiv preprint arXiv:2006.04219(2020).  Qian Lou Bian Song and Lei Jiang. 2020. AutoPrivacy: Automated Layer-wise Parameter Selection for Secure Neural Network Inference. arXiv preprint arXiv:2006.04219(2020)."},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.56"},{"key":"e_1_3_2_1_50_1","unstructured":"David Madras Elliot Creager Toniann Pitassi and Richard Zemel. 2018. Learning adversarially fair and transferable representations. arXiv preprint arXiv:1802.06309(2018).  David Madras Elliot Creager Toniann Pitassi and Richard Zemel. 2018. Learning adversarially fair and transferable representations. arXiv preprint arXiv:1802.06309(2018)."},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1145\/1367497.1367564"},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1145\/3373376.3378522"},{"key":"e_1_3_2_1_53_1","unstructured":"Fatemehsadat Mireshghallah Mohammadkazem Taram Praneeth Vepakomma Abhishek Singh Ramesh Raskar and Hadi Esmaeilzadeh. 2020. Privacy in Deep Learning: A Survey. In ArXiv Vol.\u00a0abs\/2004.12254.  Fatemehsadat Mireshghallah Mohammadkazem Taram Praneeth Vepakomma Abhishek Singh Ramesh Raskar and Hadi Esmaeilzadeh. 2020. Privacy in Deep Learning: A Survey. In ArXiv Vol.\u00a0abs\/2004.12254."},{"key":"e_1_3_2_1_54_1","volume-title":"Delphi: A Cryptographic Inference Service for Neural Networks. In USENIX Security Symposium (USENIX Security). https:\/\/www.usenix.org\/conference\/usenixsecurity20\/presentation\/mishra","author":"Mishra Pratyush","year":"2020","unstructured":"Pratyush Mishra , Ryan Lehmkuhl , Akshayaram Srinivasan , Wenting Zheng , and Raluca\u00a0Ada Popa . 2020 . Delphi: A Cryptographic Inference Service for Neural Networks. In USENIX Security Symposium (USENIX Security). https:\/\/www.usenix.org\/conference\/usenixsecurity20\/presentation\/mishra Pratyush Mishra, Ryan Lehmkuhl, Akshayaram Srinivasan, Wenting Zheng, and Raluca\u00a0Ada Popa. 2020. Delphi: A Cryptographic Inference Service for Neural Networks. In USENIX Security Symposium (USENIX Security). https:\/\/www.usenix.org\/conference\/usenixsecurity20\/presentation\/mishra"},{"key":"e_1_3_2_1_55_1","unstructured":"MLPerf Organization. 2020. MLPerf Benchmark Suite. url: https:\/\/mlperf.org.  MLPerf Organization. 2020. MLPerf Benchmark Suite. url: https:\/\/mlperf.org."},{"key":"e_1_3_2_1_56_1","volume-title":"SecureML: A System for Scalable Privacy-Preserving Machine Learning. In IEEE Symposium on Security and Privacy (S&P).","author":"Mohassel P.","unstructured":"P. Mohassel and Y. Zhang . 2017 . SecureML: A System for Scalable Privacy-Preserving Machine Learning. In IEEE Symposium on Security and Privacy (S&P). P. Mohassel and Y. Zhang. 2017. SecureML: A System for Scalable Privacy-Preserving Machine Learning. In IEEE Symposium on Security and Privacy (S&P)."},{"key":"e_1_3_2_1_57_1","volume-title":"Twelfth Symposium on Usable Privacy and Security ({SOUPS}","author":"Mondal Mainack","year":"2016","unstructured":"Mainack Mondal , Johnnatan Messias , Saptarshi Ghosh , Krishna\u00a0 P Gummadi , and Aniket Kate . 2016 . Forgetting in social media: Understanding and controlling longitudinal exposure of socially shared data . In Twelfth Symposium on Usable Privacy and Security ({SOUPS} 2016). 287\u2013299. Mainack Mondal, Johnnatan Messias, Saptarshi Ghosh, Krishna\u00a0P Gummadi, and Aniket Kate. 2016. Forgetting in social media: Understanding and controlling longitudinal exposure of socially shared data. In Twelfth Symposium on Usable Privacy and Security ({SOUPS} 2016). 287\u2013299."},{"key":"e_1_3_2_1_58_1","unstructured":"Krishna\u00a0Giri Narra Zhifeng Lin Yongqin Wang Keshav Balasubramaniam and Murali Annavaram. 2019. Privacy-Preserving Inference in Machine Learning Services Using Trusted Execution Environments. arXiv preprint arXiv:1912.03485(2019).  Krishna\u00a0Giri Narra Zhifeng Lin Yongqin Wang Keshav Balasubramaniam and Murali Annavaram. 2019. Privacy-Preserving Inference in Machine Learning Services Using Trusted Execution Environments. arXiv preprint arXiv:1912.03485(2019)."},{"key":"e_1_3_2_1_59_1","volume-title":"Facebook data harvesting scandal widens to 87 million people. online\u2013accessed","author":"Newcomb Alyssa","year":"2020","unstructured":"Alyssa Newcomb . 2018. Facebook data harvesting scandal widens to 87 million people. online\u2013accessed February 2020 , url:https:\/\/www.nbcnews.com\/tech\/tech-news\/facebook-data-harvesting-scandal-widens-87-million-people-n862771. Alyssa Newcomb. 2018. Facebook data harvesting scandal widens to 87 million people. online\u2013accessed February 2020, url:https:\/\/www.nbcnews.com\/tech\/tech-news\/facebook-data-harvesting-scandal-widens-87-million-people-n862771."},{"key":"#cr-split#-e_1_3_2_1_60_1.1","doi-asserted-by":"crossref","unstructured":"S.\u00a0A. Osia A.\u00a0S. Shamsabadi S. Sajadmanesh A. Taheri K. Katevas H.\u00a0R. Rabiee N.\u00a0D. Lane and H. Haddadi. 2020. A Hybrid Deep Learning Architecture for Privacy-Preserving Mobile Analytics. IEEE Internet of Things Journal(2020) 1-1. https:\/\/doi.org\/10.1109\/JIOT.2020.2967734 10.1109\/JIOT.2020.2967734","DOI":"10.1109\/JIOT.2020.2967734"},{"key":"#cr-split#-e_1_3_2_1_60_1.2","doi-asserted-by":"crossref","unstructured":"S.\u00a0A. Osia A.\u00a0S. Shamsabadi S. Sajadmanesh A. Taheri K. Katevas H.\u00a0R. Rabiee N.\u00a0D. Lane and H. Haddadi. 2020. A Hybrid Deep Learning Architecture for Privacy-Preserving Mobile Analytics. IEEE Internet of Things Journal(2020) 1-1. https:\/\/doi.org\/10.1109\/JIOT.2020.2967734","DOI":"10.1109\/JIOT.2020.2967734"},{"key":"e_1_3_2_1_61_1","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2018.2878698"},{"key":"e_1_3_2_1_62_1","unstructured":"Nicolas Papernot Mart\u00edn Abadi \u00dalfar Erlingsson Ian Goodfellow and Kunal Talwar. 2016. Semi-supervised Knowledge Transfer for Deep Learning from Private Training Data. arXiv preprint arXiv:1610.05755(2016). arxiv:1610.05755\u00a0[stat.ML]  Nicolas Papernot Mart\u00edn Abadi \u00dalfar Erlingsson Ian Goodfellow and Kunal Talwar. 2016. Semi-supervised Knowledge Transfer for Deep Learning from Private Training Data. arXiv preprint arXiv:1610.05755(2016). arxiv:1610.05755\u00a0[stat.ML]"},{"key":"e_1_3_2_1_63_1","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"e_1_3_2_1_64_1","unstructured":"Nicolas Papernot Shuang Song Ilya Mironov Ananth Raghunathan Kunal Talwar and \u00dalfar Erlingsson. 2018. Scalable Private Learning with PATE. arXiv preprint arXiv:1802.08908(2018).  Nicolas Papernot Shuang Song Ilya Mironov Ananth Raghunathan Kunal Talwar and \u00dalfar Erlingsson. 2018. Scalable Private Learning with PATE. arXiv preprint arXiv:1802.08908(2018)."},{"key":"e_1_3_2_1_65_1","unstructured":"Maarten\u00a0G. Poirot Praneeth Vepakomma K. Chang J. Kalpathy-Cramer R. Gupta and R. Raskar. 2019. Split Learning for collaborative deep learning in healthcare. ArXiv abs\/1912.12115(2019).  Maarten\u00a0G. Poirot Praneeth Vepakomma K. Chang J. Kalpathy-Cramer R. Gupta and R. Raskar. 2019. Split Learning for collaborative deep learning in healthcare. ArXiv abs\/1912.12115(2019)."},{"key":"e_1_3_2_1_66_1","volume-title":"Privacy-Preserving Crowd-Sourcing of Web Searches with Private Data Donor. In The World Wide Web Conference","author":"Primault Vincent","year":"2019","unstructured":"Vincent Primault , Vasileios Lampos , Ingemar Cox , and Emiliano De\u00a0Cristofaro . 2019 . Privacy-Preserving Crowd-Sourcing of Web Searches with Private Data Donor. In The World Wide Web Conference ( San Francisco, CA, USA) (WWW \u201919). Association for Computing Machinery, New York, NY, USA, 1487\u20131497. https:\/\/doi.org\/10.1145\/3308558.3313474 10.1145\/3308558.3313474 Vincent Primault, Vasileios Lampos, Ingemar Cox, and Emiliano De\u00a0Cristofaro. 2019. Privacy-Preserving Crowd-Sourcing of Web Searches with Private Data Donor. In The World Wide Web Conference (San Francisco, CA, USA) (WWW \u201919). Association for Computing Machinery, New York, NY, USA, 1487\u20131497. https:\/\/doi.org\/10.1145\/3308558.3313474"},{"key":"e_1_3_2_1_67_1","unstructured":"Swaroop Ramaswamy Om Thakkar Rajiv Mathews Galen Andrew H\u00a0Brendan McMahan and Fran\u00e7oise Beaufays. 2020. Training production language models without memorizing user data. arXiv preprint arXiv:2009.10031(2020).  Swaroop Ramaswamy Om Thakkar Rajiv Mathews Galen Andrew H\u00a0Brendan McMahan and Fran\u00e7oise Beaufays. 2020. Training production language models without memorizing user data. arXiv preprint arXiv:2009.10031(2020)."},{"key":"e_1_3_2_1_68_1","doi-asserted-by":"publisher","DOI":"10.1109\/MCC.2015.46"},{"key":"e_1_3_2_1_69_1","volume-title":"MLPerf Inference Benchmark. In International Symposium on Computer Architecture (ISCA).","author":"Reddi Vijay\u00a0Janapa","year":"2020","unstructured":"Vijay\u00a0Janapa Reddi , Christine Cheng , David Kanter , Peter Mattson , Guenther Schmuelling , Carole-Jean Wu , Brian Anderson , Maximilien Breughe , Mark Charlebois , William Chou , 2020 . MLPerf Inference Benchmark. In International Symposium on Computer Architecture (ISCA). Vijay\u00a0Janapa Reddi, Christine Cheng, David Kanter, Peter Mattson, Guenther Schmuelling, Carole-Jean Wu, Brian Anderson, Maximilien Breughe, Mark Charlebois, William Chou, 2020. MLPerf Inference Benchmark. In International Symposium on Computer Architecture (ISCA)."},{"key":"e_1_3_2_1_70_1","volume-title":"Ariann: Low-interaction privacy-preserving deep learning via function secret sharing. arXiv preprint arXiv:2006.04593(2020).","author":"Ryffel Th\u00e9o","year":"2020","unstructured":"Th\u00e9o Ryffel , David Pointcheval , and Francis Bach . 2020 . Ariann: Low-interaction privacy-preserving deep learning via function secret sharing. arXiv preprint arXiv:2006.04593(2020). Th\u00e9o Ryffel, David Pointcheval, and Francis Bach. 2020. Ariann: Low-interaction privacy-preserving deep learning via function secret sharing. arXiv preprint arXiv:2006.04593(2020)."},{"key":"e_1_3_2_1_71_1","first-page":"4517","article-title":"Partially encrypted deep learning using functional encryption","volume":"32","author":"Ryffel Th\u00e9o","year":"2019","unstructured":"Th\u00e9o Ryffel , David Pointcheval , Francis Bach , Edouard Dufour-Sans , and Romain Gay . 2019 . Partially encrypted deep learning using functional encryption . Advances in Neural Information Processing Systems 32 (2019), 4517 \u2013 4528 . Th\u00e9o Ryffel, David Pointcheval, Francis Bach, Edouard Dufour-Sans, and Romain Gay. 2019. Partially encrypted deep learning using functional encryption. Advances in Neural Information Processing Systems 32 (2019), 4517\u20134528.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_1_72_1","unstructured":"Sina Sajadmanesh and Daniel Gatica-Perez. 2020. When Differential Privacy Meets Graph Neural Networks. arXiv preprint arXiv:2006.05535(2020).  Sina Sajadmanesh and Daniel Gatica-Perez. 2020. When Differential Privacy Meets Graph Neural Networks. arXiv preprint arXiv:2006.05535(2020)."},{"key":"e_1_3_2_1_73_1","doi-asserted-by":"publisher","DOI":"10.1145\/3041021.3055137"},{"key":"e_1_3_2_1_74_1","volume-title":"Privacy-Preserving Deep Learning. In ACM Conference on Computer and Communications Security (CCS).","author":"Shokri Reza","year":"2015","unstructured":"Reza Shokri and Vitaly Shmatikov . 2015 . Privacy-Preserving Deep Learning. In ACM Conference on Computer and Communications Security (CCS). Reza Shokri and Vitaly Shmatikov. 2015. Privacy-Preserving Deep Learning. In ACM Conference on Computer and Communications Security (CCS)."},{"key":"e_1_3_2_1_75_1","volume-title":"Membership Inference Attacks Against Machine Learning Models. In IEEE Symposium on Security and Privacy (S&P).","author":"Shokri R.","unstructured":"R. Shokri , M. Stronati , C. Song , and V. Shmatikov . 2017 . Membership Inference Attacks Against Machine Learning Models. In IEEE Symposium on Security and Privacy (S&P). R. Shokri, M. Stronati, C. Song, and V. Shmatikov. 2017. Membership Inference Attacks Against Machine Learning Models. In IEEE Symposium on Security and Privacy (S&P)."},{"key":"e_1_3_2_1_76_1","unstructured":"Karen Simonyan and Andrew Zisserman. 2014. Very Deep Convolutional Networks for Large-Scale Image Recognition. arXiv preprint arXiv:1409.1556(2014).  Karen Simonyan and Andrew Zisserman. 2014. Very Deep Convolutional Networks for Large-Scale Image Recognition. arXiv preprint arXiv:1409.1556(2014)."},{"key":"e_1_3_2_1_77_1","unstructured":"Abhishek Singh Praneeth Vepakomma Otkrist Gupta and R. Raskar. 2019. Detailed comparison of communication efficiency of split learning and federated learning. ArXiv abs\/1909.09145(2019).  Abhishek Singh Praneeth Vepakomma Otkrist Gupta and R. Raskar. 2019. Detailed comparison of communication efficiency of split learning and federated learning. ArXiv abs\/1909.09145(2019)."},{"key":"e_1_3_2_1_78_1","volume-title":"Learning Light-Weight Edge-Deployable Privacy Models. 2018 IEEE International Conference on Big Data (Big Data)","author":"Lim Yeon","year":"2018","unstructured":"Yeon sup Lim , M. Srivatsa , S. Chakraborty , and I. Taylor . 2018 . Learning Light-Weight Edge-Deployable Privacy Models. 2018 IEEE International Conference on Big Data (Big Data) ( 2018 ), 1290\u20131295. Yeon sup Lim, M. Srivatsa, S. Chakraborty, and I. Taylor. 2018. Learning Light-Weight Edge-Deployable Privacy Models. 2018 IEEE International Conference on Big Data (Big Data) (2018), 1290\u20131295."},{"key":"e_1_3_2_1_79_1","doi-asserted-by":"publisher","DOI":"10.5555\/2627435.2627444"},{"key":"e_1_3_2_1_80_1","volume-title":"2020 ACM\/IEEE 47th Annual International Symposium on Computer Architecture (ISCA). 721\u2013734","author":"Taram M.","year":"2020","unstructured":"M. Taram , A. Venkat , and D. Tullsen . 2020. Packet Chasing: Spying on Network Packets over a Cache Side-Channel . In 2020 ACM\/IEEE 47th Annual International Symposium on Computer Architecture (ISCA). 721\u2013734 . https:\/\/doi.org\/10.1109\/ISCA45697. 2020 .00065 10.1109\/ISCA45697.2020.00065 M. Taram, A. Venkat, and D. Tullsen. 2020. Packet Chasing: Spying on Network Packets over a Cache Side-Channel. In 2020 ACM\/IEEE 47th Annual International Symposium on Computer Architecture (ISCA). 721\u2013734. https:\/\/doi.org\/10.1109\/ISCA45697.2020.00065"},{"key":"e_1_3_2_1_81_1","volume-title":"Thompson and Charlie Warzel","author":"A.","year":"2019","unstructured":"Stuart\u00a0 A. Thompson and Charlie Warzel . 2019 . The Privacy Project: Twelve Million Phones, One Dataset, Zero Privacy . online\u2013accessed February 2020, url: https:\/\/www.nytimes.com\/interactive\/2019\/12\/19\/opinion\/location-tracking-cell-phone.html. Stuart\u00a0A. Thompson and Charlie Warzel. 2019. The Privacy Project: Twelve Million Phones, One Dataset, Zero Privacy. online\u2013accessed February 2020, url: https:\/\/www.nytimes.com\/interactive\/2019\/12\/19\/opinion\/location-tracking-cell-phone.html."},{"key":"e_1_3_2_1_82_1","volume-title":"Verifiable and Private Execution of Neural Networks in Trusted Hardware. In International Conference on Learning Representations (ICLR). https:\/\/openreview.net\/forum?id=rJVorjCcKQ","author":"Tramer Florian","year":"2019","unstructured":"Florian Tramer and Dan Boneh . 2019 . Slalom: Fast , Verifiable and Private Execution of Neural Networks in Trusted Hardware. In International Conference on Learning Representations (ICLR). https:\/\/openreview.net\/forum?id=rJVorjCcKQ Florian Tramer and Dan Boneh. 2019. Slalom: Fast, Verifiable and Private Execution of Neural Networks in Trusted Hardware. In International Conference on Learning Representations (ICLR). https:\/\/openreview.net\/forum?id=rJVorjCcKQ"},{"key":"e_1_3_2_1_83_1","doi-asserted-by":"publisher","DOI":"10.1145\/3321705.3329830"},{"key":"e_1_3_2_1_84_1","doi-asserted-by":"crossref","unstructured":"Praneeth Vepakomma Abhishek Singh Otkrist Gupta and Ramesh Raskar. 2020. NoPeek: Information leakage reduction to share activations in distributed deep learning. ArXiv abs\/2008.09161(2020).  Praneeth Vepakomma Abhishek Singh Otkrist Gupta and Ramesh Raskar. 2020. NoPeek: Information leakage reduction to share activations in distributed deep learning. ArXiv abs\/2008.09161(2020).","DOI":"10.1109\/ICDMW51313.2020.00134"},{"key":"e_1_3_2_1_85_1","volume-title":"FALCON: Honest-Majority Maliciously Secure Framework for Private Deep Learning. arXiv preprint arXiv:2004.02229(2020).","author":"Wagh Sameer","year":"2020","unstructured":"Sameer Wagh , Shruti Tople , Fabrice Benhamouda , Eyal Kushilevitz , Prateek Mittal , and Tal Rabin . 2020 . FALCON: Honest-Majority Maliciously Secure Framework for Private Deep Learning. arXiv preprint arXiv:2004.02229(2020). Sameer Wagh, Shruti Tople, Fabrice Benhamouda, Eyal Kushilevitz, Prateek Mittal, and Tal Rabin. 2020. FALCON: Honest-Majority Maliciously Secure Framework for Private Deep Learning. arXiv preprint arXiv:2004.02229(2020)."},{"key":"e_1_3_2_1_86_1","volume-title":"Not Just Privacy. ACM International Conference on Knowledge Discovery and Data Mining (KDD) (2018","author":"Wang Ji","year":"2018","unstructured":"Ji Wang , Jianguo Zhang , Weidong Bao , Xiaomin Zhu , Bokai Cao , and Philip\u00a0 S. Yu . 2018 . Not Just Privacy. ACM International Conference on Knowledge Discovery and Data Mining (KDD) (2018 ). https:\/\/doi.org\/10.1145\/3219819.3220106 10.1145\/3219819.3220106 Ji Wang, Jianguo Zhang, Weidong Bao, Xiaomin Zhu, Bokai Cao, and Philip\u00a0S. Yu. 2018. Not Just Privacy. ACM International Conference on Knowledge Discovery and Data Mining (KDD) (2018). https:\/\/doi.org\/10.1145\/3219819.3220106"},{"key":"e_1_3_2_1_87_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.463"},{"key":"e_1_3_2_1_88_1","doi-asserted-by":"publisher","DOI":"10.1145\/1526709.1526781"}],"event":{"name":"WWW '21: The Web Conference 2021","location":"Ljubljana Slovenia","acronym":"WWW '21","sponsor":["SIGWEB ACM Special Interest Group on Hypertext, Hypermedia, and Web"]},"container-title":["Proceedings of the Web Conference 2021"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3442381.3449965","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3442381.3449965","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T21:24:44Z","timestamp":1750195484000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3442381.3449965"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,4,19]]},"references-count":89,"alternative-id":["10.1145\/3442381.3449965","10.1145\/3442381"],"URL":"https:\/\/doi.org\/10.1145\/3442381.3449965","relation":{},"subject":[],"published":{"date-parts":[[2021,4,19]]},"assertion":[{"value":"2021-06-03","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}